Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

@secretlint/secretlint-rule-npm

Package Overview
Dependencies
Maintainers
0
Versions
80
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@secretlint/secretlint-rule-npm

A secretlint rule for npm.

  • 9.0.0
  • latest
  • Source
  • npm
  • Socket score

Version published
Maintainers
0
Created
Source

@secretlint/secretlint-rule-npm

A secretlint rule for npm.

Install

Install with npm:

npm install @secretlint/secretlint-rule-npm

Usage

Via .secretlintrc.json(Recommended)

{
    "rules": [
        {
            "id": "@secretlint/secretlint-rule-npm"
        }
    ]
}

MessageIDs

PackageJSON_xOauthToken

found GitHub Token: {{TOKEN}}

Disallow to use https://<token>@github.com/owner/repo.git in package.json or package-lock.json.

Often, https://<token>@github.com/owner/repo.git is used for installing module from private repository.

If you want to use some module as private, please use private registry like npm, GitHub Package Registry, or Verdaccio.

Npmrc_authToken

found npmrc authToken: {{TOKEN}}

Disallow to include <registry>:_authToken=<TOKEN> in .npmrc.

The TOKEN is credential data.

NPM_ACCESS_TOKEN

found npm access token: {{TOKEN}}

Disallow to include npm access token.

The TOKEN is credential data.

Options

Changelog

See Releases page.

Running tests

Install devDependencies and Run npm test:

npm test

Contributing

Pull requests and stars are always welcome.

For bugs and feature requests, please create an issue.

  1. Fork it!
  2. Create your feature branch: git checkout -b my-new-feature
  3. Commit your changes: git commit -am 'Add some feature'
  4. Push to the branch: git push origin my-new-feature
  5. Submit a pull request :D

Author

License

MIT © azu

Keywords

FAQs

Package last updated on 14 Oct 2024

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc